Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
77.302 exploits
Exploit-DB
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
CVE-2020-11027MEDIUMwebappsphp19 jun 2023
Password reset links invalidation issue in WordPress
38RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL19 jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC
overgrowncarrot1/CVE-2021-22911
CVE-2021-2291119 jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2291119 jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
CVE-2023-23956MEDIUMwebappshardware19 jun 2023
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-32315HIGHbajo ataque18 jun 2023
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC57
Openfire Console Authentication Bypass Vulnerability with RCE plugin
CVE-2023-32315HIGHbajo ataque18 jun 2023
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC7
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RIESGO
abrir
GitHub PoC1
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RIESGO
abrir
GitHub PoC23
FortiOS 管理界面中的堆内存下溢导致远程代码执行
CVE-2023-25610CRITICAL17 jun 2023
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676317 jun 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-30777HIGH17 jun 2023
WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27997CRITICALbajo ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC
CVE-2023-34600
CVE-2023-34600CRITICAL16 jun 2023
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
53RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27997CRITICALbajo ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC6
Repository with everything I have tracking the impact of MOVEit CVE-2023-34362
CVE-2023-34362CRITICALbajo ataqueransomware16 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC134
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
CVE-2023-27997CRITICALbajo ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC27
POC FortiOS SSL-VPN buffer overflow vulnerability
CVE-2023-27997CRITICALbajo ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
Metasploit600
Rudder Server SQLI Remote Code Execution
CVE-2023-30625HIGH16 jun 2023
rudder-server vulnerable to SQL Injection
58RIESGO
abrir
GitHub PoC15
SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates
CVE-2023-23333CRITICAL16 jun 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque16 jun 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23333CRITICAL16 jun 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
GitHub PoC4
Joomla未授权访问漏洞
CVE-2023-23752MEDIUMbajo ataque16 jun 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL15 jun 2023
Code Injection in pyload/pyload
85RIESGO
abrir
GitHub PoC
Exploit for CVE-2022-44136 for chcking security of your site
CVE-2022-44136CRITICAL15 jun 2023
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-32315HIGHbajo ataque15 jun 2023
Openfire administration console authentication bypass
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2464715 jun 2023
Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login
38RIESGO
abrir
GitHub PoC1
overgrowncarrot1/CVE-2023-0297
CVE-2023-0297CRITICAL15 jun 2023
Code Injection in pyload/pyload
85RIESGO
abrir
GitHub PoC
Samba 3.0.20
CVE-2007-244715 jun 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC2
5rGJ5aCh5oCq5YW9/CVE-2023-32315exp
CVE-2023-32315HIGHbajo ataque15 jun 2023
Openfire administration console authentication bypass
100RIESGO
abrir
anteriorpágina 488 / 2577siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.